Analyst command view

MSRC Driver CVE Board

Latest-state board for filtered MSRC CVEs from 2020-01-01 to today, tuned for fast triage across module, CWE, release window, exploitation signal, and acknowledgement context.

Live snapshot
Last Sync
2026-05-20T07:39:30Z
Freshness
1 day(s) ago
Refresh Policy
24h baseline + release watch
Storage
Latest snapshot only
Rows In View
20
Current result set after filter and search.
Exploited Flagged
17
Rows with a non-empty exploitation signal.
Distinct CWE
2
Unique weakness classes in this view.
Modules
16
Unique inferred driver or component labels.
Reset
Active filters CWE CWE-269: Improper Privilege Management Clear filters
Release Month
May 2026
1 CVE | last update 1 day(s) ago
Release 2026-05-07 Other / OOB Count 1
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2026-24072
Apache HTTP Server: mod_rewrite
No latest release note
Apache HTTP Server: mod_rewrite elevation of privileges via ap_expr
No CVSS vector published
2026-05-07 - -
Release Month
April 2026
2 CVE | last update 1 day(s) ago
Release 2026-04-14 Patch Tuesday Count 2
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2026-32212
Universal Plug and Play (upnp.dll)
Exploitation Less Likely
Universal Plug and Play (upnp.dll) Information Disclosure Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C
2026-04-14 No
Reported By
Anonymous
CVE-2026-32181
Connected User Experiences and Telemetry Service
Exploitation Less Likely
Connected User Experiences and Telemetry Service Denial of Service Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C
2026-04-14 No
Reported By
Release Month
February 2026
1 CVE | last update 1 day(s) ago
Release 2026-02-10 Patch Tuesday Count 1
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2026-21533
Windows Remote Desktop Services
Exploitation Detected
Windows Remote Desktop Services Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C
2026-02-10 Yes
Release Month
November 2025
1 CVE | last update 1 day(s) ago
Release 2025-11-11 Patch Tuesday Count 1
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2025-59514
Microsoft Streaming Service Proxy
Exploitation Unlikely
Microsoft Streaming Service Proxy Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2025-11-11 No
Reported By
Release Month
June 2025
2 CVE | last update 1 day(s) ago
Release 2025-06-10 Patch Tuesday Count 2
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2025-33067
Windows Task Scheduler
Exploitation Less Likely
Windows Task Scheduler Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2025-06-10 No
Reported By
Alexander Pudwill
CVE-2025-47955
Windows Remote Access Connection Manager
Exploitation Less Likely
Windows Remote Access Connection Manager Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2025-06-10 No
Reported By
Sergey Bliznyuk with Positive Technologies
Release Month
May 2025
1 CVE | last update 1 day(s) ago
Release 2025-05-13 Patch Tuesday Count 1
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2025-27468
Windows Kernel-Mode Driver
Exploitation Less Likely
Windows Kernel-Mode Driver Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2025-05-13 No
Reported By
Naceri with MSRC Vulnerabilities & Mitigations
Release Month
January 2025
2 CVE | last update 1 day(s) ago
Release 2025-01-14 Patch Tuesday Count 2
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2025-21343
Windows Web Threat Defense User Service
Exploitation Less Likely
Windows Web Threat Defense User Service Information Disclosure Vulnerability
CVSS vector: AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C
2025-01-14 No
CVE-2025-21287
Windows Installer
Exploitation Less Likely
Windows Installer Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C
2025-01-14 No
Reported By
Release Month
September 2024
1 CVE | last update 1 day(s) ago
Release 2024-09-10 Patch Tuesday Count 1
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2024-38014
Windows Installer
Exploitation Detected
Windows Installer Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C
2024-09-10 Yes
Release Month
May 2024
1 CVE | last update 1 day(s) ago
Release 2024-05-14 Patch Tuesday Count 1
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2024-30007
Microsoft Brokering File System
Exploitation Less Likely
Microsoft Brokering File System Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C
2024-05-14 No
Reported By
Naceri with MSRC Vulnerabilities & Mitigations
Release Month
April 2024
3 CVE | last update 1 day(s) ago
Release 2024-04-09 Patch Tuesday Count 3
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2024-29052
Windows Storage
Exploitation Less Likely
Windows Storage Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2024-04-09 No
Reported By
Christopher Lee (cubeof11)
CVE-2024-28905
Microsoft Brokering File System
Exploitation Less Likely
Microsoft Brokering File System Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C
2024-04-09 No
Reported By
Naceri with MSRC Vulnerabilities & Mitigations
CVE-2024-28904
Microsoft Brokering File System
Exploitation Less Likely
Microsoft Brokering File System Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C
2024-04-09 No
Reported By
Naceri with MSRC Vulnerabilities & Mitigations
Release Month
March 2024
1 CVE | last update 1 day(s) ago
Release 2024-03-12 Patch Tuesday Count 1
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2024-26169
Windows Error Reporting Service
Exploitation Less Likely
Windows Error Reporting Service Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2024-03-12 No
Reported By
Naceri with MSRC Vulnerabilities & Mitigations
Release Month
October 2023
1 CVE | last update 1 day(s) ago
Release 2023-10-10 Patch Tuesday Count 1
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2023-36721
Windows Error Reporting Service
Exploitation Less Likely
Windows Error Reporting Service Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2023-10-10 No
Reported By
Release Month
March 2023
1 CVE | last update 1 day(s) ago
Release 2023-03-14 Patch Tuesday Count 1
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2023-23412
Windows Accounts Picture
Exploitation Less Likely
Windows Accounts Picture Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2023-03-14 No
Reported By
Filip Dragović with Infigo IS
Release Month
May 2022
1 CVE | last update 1 day(s) ago
Release 2022-05-12 Other / OOB Count 1
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2022-1227
A privilege escalation flaw was found in Podman. This flaw allows an attacker to publish a malicious image to a public registry. Once this image is downloaded by a potential victim the vulnerability is triggered after a user runs the 'podman top' command. This action gives the attacker access to the host filesystem leading to
No latest release note
A privilege escalation flaw was found in Podman. This flaw allows an attacker to publish a malicious image to a public registry. Once this image is downloaded by a potential victim the vulnerability is triggered after a user runs the 'podman top' command. This action gives the attacker access to the host filesystem leading to information disclosure or denial of service.
CVSS vector: AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
2022-05-12 - -
Release Month
August 2020
1 CVE | last update 1 day(s) ago
Release 2020-08-18 Other / OOB Count 1
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2018-10906
In fuse before versions 2.9.8 and 3.x before 3.2.5 fusermount is vulnerable to a restriction bypass when SELinux is active. This allows non-root users to mount a FUSE file system with the 'allow_other' mount option regardless of whether 'user_allow_other' is set in the fuse configuration. An attacker may use this flaw to mount a FUSE file system accessible by other users and trick them into accessing files on that file system possibly causing
No latest release note
In fuse before versions 2.9.8 and 3.x before 3.2.5 fusermount is vulnerable to a restriction bypass when SELinux is active. This allows non-root users to mount a FUSE file system with the 'allow_other' mount option regardless of whether 'user_allow_other' is set in the fuse configuration. An attacker may use this flaw to mount a FUSE file system accessible by other users and trick them into accessing files on that file system possibly causing Denial of Service or other unspecified effects.
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
2020-08-18 - -